Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2025-36144
IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.
Watsonx.data
Mitigation only
HIGH 8.8
CVE-2025-36202
IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to t…
Webmethods Integration
Mitigation only
MEDIUM 5.4
CVE-2025-36037
IBM webMethods Integration 10.15 and 11.1
is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una…
Webmethods Integration
Mitigation only
HIGH 7.2
CVE-2025-36143
IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation …
Watsonx.data
Mitigation only
MEDIUM 5.5
CVE-2025-36244
IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the sy…
Vios
Mitigation only
MEDIUM 5.1
CVE-2025-36035
IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to…
Powervm Hypervisor
Mitigation only
MEDIUM 5.4
CVE-2025-36125
IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authen…
Hardware Management Console
Mitigation only
MEDIUM 5.3
CVE-2025-36003
IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error me…
Security Verify Governance
Mitigation only
CRITICAL 9.3
CVE-2025-2697
IBM Cognos Command Center 10.2.4.1 and 10.2.5
could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuadi…
Cognos Command Center
Mitigation only
HIGH 7.8
CVE-2025-1994
IBM Cognos Command Center 10.2.4.1 and 10.2.5
could allow a local user to execute arbitrary code on the system due to the use of unsafe use of th…
Cognos Command Center
Mitigation only
MEDIUM 6.1
CVE-2025-1494
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi…
Cognos Command Center
Mitigation only
HIGH 7.8
CVE-2025-33120
IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution wi…
Qradar Incident Forensics
Mitigation only
MEDIUM 5.4
CVE-2025-36042
IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary…
Qradar Incident Forensics
Mitigation only
MEDIUM 5.4
CVE-2025-1142
IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized r…
Edge Application Manager
Mitigation only
MEDIUM 5.4
CVE-2025-33008
IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authent…
Sterling B2b Integrator
Mitigation only
MEDIUM 5.4
CVE-2025-36088
IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an auth…
Storage Ts4500 Library Firmware
Mitigation only
HIGH 8.8
CVE-2025-36119
IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due …
I
Mitigation only
MEDIUM 6.5
CVE-2025-36023
IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive…
Cloud Pak For Business Automation
Mitigation only
HIGH 7.5
CVE-2025-36020
IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential info…
Guardium Data Protection
Mitigation only
CRITICAL 9.8
CVE-2025-3320
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A re…
Tivoli Monitoring
Mitigation only
CRITICAL 9.8
CVE-2025-3354
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A re…
Tivoli Monitoring
Mitigation only
MEDIUM 6.1
CVE-2024-52890
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.
Engineering Lifecycle Optimization
Mitigation only
HIGH 7.4
CVE-2025-2824
IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using an…
Operational Decision Manager
Mitigation only
MEDIUM 5.4
CVE-2025-33118
IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed…
Qradar Security Information And Event Manager
Mitigation only
HIGH 7.8
CVE-2025-33092
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2
is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local u…
Db2
Mitigation only
HIGH 7.5
CVE-2025-33114
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2
is vulnerable to denial of service with a specially crafted query under certain non-default conditio…
Db2
Mitigation only
HIGH 7.5
CVE-2025-36010
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2
could allow an unauthenticated user to cause a denial of service due to executable segments that are w…
Db2
Mitigation only
HIGH 7.5
CVE-2025-2533
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially c…
Db2
Mitigation only
HIGH 7.5
CVE-2024-49342
IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account cred…
Informix Dynamic Server
Mitigation only
MEDIUM 5.4
CVE-2024-49343
IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, w…
Informix Dynamic Server
Mitigation only